University of Nottingham
CriticalConfirmedEducation
In June 2026, University of Nottingham suffered a data breach. 454,635 accounts were affected. The exposed data includes identity documents, dates of birth, health data, email addresses, connection data, names, phone numbers, postal addresses, purchase histories and account identifiers.
- Disclosed on
- June 10, 2026
- Incident dated
- June 9, 2026
- Accounts affected
- 454,635
- Sector
- Education
- Country
- United Kingdom
- Cause
- Undisclosed
Exposed data
- Identity document
- Date of birth
- Health data
- Email address
- Connection data (IP, logs)
- Full name
- Phone number
- Postal address
- Order history
- Customer ID
You are only affected if you had an account or an order with this organisation.
What you can do
- Expect phishing attempts quoting your name and this company. A message that knows your details is not legitimate for that reason.
- These documents enable identity theft, and cannot be reissued at will. Keep the notification letter: it proves where the leak came from if an account is opened in your name.
- Health data is “special category” data under the GDPR: a leak opens a right to compensation, and the organisation must notify the DPA within 72 hours.
- You can ask the organisation exactly what was exposed about you (right of access), and complain to the DPA if no answer comes within a month.
Sources
Entry built from Have I Been Pwned’s structured data, with no model rewriting. Spotted an error, or have a correction? Write to us and the entry will be fixed. Contact